capgo-native-builds

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues or malicious patterns were identified in this skill.
  • [COMMAND_EXECUTION]: The skill uses the official vendor package @capgo/cli via npx for cloud build orchestration, which is normal functionality matching the skill author context.
  • [CREDENTIALS_UNSAFE]: The instructions explicitly direct the agent to treat API keys, P12 passwords, keystores, and service accounts as secrets, use placeholders in examples, and avoid echoing secrets back to the user. This is an appropriate security practice and the static analysis flag for concealment is a false positive.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:40 AM
Security Audit — agent-trust-hub — capgo-native-builds